Mobile Device Management (MDM) Policies. Best Practices Guide.

Transcription

1 Mobile Device Management (MDM) Policies Best Practices Guide

2 Copyright 2014 Fiberlink Communications Corporation. All rights reserved. This document contains proprietary and confidential information of Fiberlink, an IBM company. No part of this document may be used, disclosed, distributed, transmitted, stored in any retrieval system, copied or reproduced in any way or form, including but not limited to photocopy, photographic, magnetic, electronic or other record, without the prior written permission of Fiberlink. This document is provided for informational purposes only and the information herein is subject to change without notice. Please report any errors to Fiberlink. Fiberlink will not provide any warranties covering this information and specifically disclaims any liability in connection with this document. Fiberlink, MaaS360, associated logos, and the names of the products and services of Fiberlink are trademarks or service marks of Fiberlink and may be registered in certain jurisdictions. All other names, marks, brands, logos, and symbols may be trademarks or registered trademarks or service marks of their respective owners. Use of any or all of the above is subject to the specific terms and conditions of the Agreement. Copyright 2014 Fiberlink, 1787 Sentry Parkway West, Building Eighteen, Suite 200, Blue Bell, PA All rights reserved. 2

4 Best Practice #5: Keep a Watchful Eye on Apps Best Practice #6: Use TouchDown for Setting up (Android Only) Best Practice #7: Distribute Settings Over the Air (OTA) Best Practice #8: Warn First, Then Remediate Policy Violations Best Practice #9: Test Your Policies Best Practice #10: Monitor Your Devices

5 Introduction This document is designed to give you Mobile Device Management (MDM) best practices we ve developed while working with our extensive customer base. It will also show you how MaaS360 can help you. MaaS360 is designed to give you maximum control over mobile devices, so you can reduce risks to your corporate data without jeopardizing employee productivity. It will watch over your devices, both employee-owned and those provided by the corporation, making sure they comply with corporate security policies. You can set it up so that you don t have to do anything if devices fall out of compliance MaaS360 can take action automatically. Some of these actions include: Warning the administrator that there could be a problem Sending a message telling the user to do something Preventing the user from accessing his corporate account from his device Wiping corporate data, apps and documents from the device while leaving personal data untouched For example, you can create a policy listing restricted, approved and required apps for your users. If they are out of compliance, the device can be restricted from accessing corporate accounts, Wi-Fi, and the VPN after 24 hours. You can then assign this policy to all the active Android devices that have reported in to MaaS360 in the last seven days. Best Practice #1: Know Your Industry s Regulations Many of your decisions will be grounded in the regulations for your industry. For example, if you are in the Healthcare industry, you ll need to comply with the requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH Act). Armed with this knowledge you can set up your policies. Most companies only have a few policies: 1. Corporate devices 2. Personal devices 3. ios devices 4. Android devices Keep it simple. Many of your settings will be the same for each policy, because the requirements of your industry will be the same. Maintenance will be easier if, as much as it is possible, you treat all your users the same way. 5

6 Best Practice #2: Require Passcodes Of all the ways to protect your devices, requiring passcodes probably gets you the greatest results with the least effort. Small devices like tablets and smartphones are easy to lose, so the chances of them ending up in someone else s hands are pretty good. The Options Types of Passcodes Name Description Example Simple Repeating, ascending or descending values 1111, 2233, 1234, 0987, xyz Numeric Requires at least one number 184, 1066, 1490, xyz1 Alphanumeric Requires at least one letter and one number itbgc11, g2t, pick1e Complex, Alphanumeric with Special Characters Pattern Requires at least one letter, one number, and a special character. May also require at least one uppercase and one lowercase letter Android only. The device displays rows of dots, and the user slides his finger across them in a certain order to gain access Tlso4r#, wntg?stio2f, R!h9 Minimum Length You can have passcodes from one to sixteen characters long. Longer passcodes are more secure, but if you require your users to have very long passcodes your users will have trouble remembering them. Passcode Expiration You can require your users to enter a new passcode after a specified period of time. When time s up, they ll have to change it. Passcode Reuse You can prevent your users from using the same two or three passcodes over and over. 6

7 1. Require passcodes on all devices that will access corporate resources. Passcodes are your first line of defense. 2. The most secure passcodes are complex. We recommend requiring your users to have alphanumeric passwords with at least one uppercase and one lowercase letter, even though your industry may not require them yet. 3. We recommend that passcodes be at least four or five characters long. 4. We recommend that you set up passcode expiration. 5. Requiring a different passcode every time they change it is probably overkill, but you should probably set up some reuse restrictions. Use your industry s rules and regulations as your guide. MaaS360 allows you to set up passcode policies quickly and easily. We ve found that most of our customers don t need many. We provide two default policies to help you: one for ios devices and one for Androids. To make your changes, just edit one of MaaS360 s default policies. There are even more options than we discussed above. These will come in handy if your industry has very stringent passcode requirements. With a few clicks you can make your passcode policy a reality. 7

8 Best Practice #3: Enforce Encryption Apple s ios provides block-level encryption on all devices that are 3GS and higher. When a user sets up a passcode, however, it starts using the file-level encryption data protection element. As a result, if you are requiring your users to protect their ios devices with a passcode, you don t really need to worry about encryption. ios will handle it automatically. Google s Android operating system is a different matter. Some devices don t support encryption at all (usually the earlier models and operating system versions). To enforce encryption, you might have to refuse to support some Android devices. Encryption is a must-have. You may encounter some resistance if you don t support devices that cannot be encrypted, but it s worth it in the end to know that your data is safe. We recommend you prevent any devices that cannot be encrypted from connecting to your corporate resources. MaaS360 can identify the Android devices that cannot be encrypted. You can also use MaaS360 s Compliance Engine to block devices from accessing corporate resources. 8

9 Best Practice #4: Restrict Device Features as Necessary If your industry requires it, you may need to disable certain features on the devices. For example, you might want to disable cameras to protect proprietary information if your users work in a plant. The operating system makes a difference here, too, because device features are different. For example, you may want to prevent ios users from storing data to icloud or from accessing Siri when the device is locked. If these devices are owned by your employees, not given out by the company, you may want to restrict as little as possible. We recommend restricting: Accessing Siri when the device is locked Bluetooth (or making it non-discoverable) Mock locations Syncing documents to icloud (although we don t recommend restricting backing up other things to icloud or syncing using Photo Stream ) Camera, screen captures, and YouTube if it is required for your industry On ios devices, we recommend the following settings for Safari: Leave the fraud warnings on Block pop-ups Accept cookies only from visited sites MaaS360 provides a number of choices for your devices. You can quickly and easily put into place the safeguards to protect devices. MaaS360 has even more choices than we ve discussed, so you can make sure you re in compliance with your industry s requirements. 9

10 Best Practice #5: Keep a Watchful Eye on Apps Apps can improve productivity enormously, but they can also open up your organization to risks. Some apps like Dropbox allow your users to store documents outside your span of control. It makes things easier for them, but what happens if the employees leave the company? It might make sense for you to restrict some apps, depending on what is dictated by your industry or corporate security policies. You might also want to allow other apps. Some of our customers also require employees to have the same collaboration tools so teams can work together. 1. Use your MDM solution to restrict, allow and require apps you need to encourage productivity while keeping your corporate data safe. 2. If your MDM solution has one, use a corporate app catalog to push helpful apps to your users. Policies allow you to specify restricted, allowed and required apps. 10

11 MaaS360 also offers an App Catalog that you can use to push market or enterprise apps directly to your devices. The App Catalog is set up so it keeps personal apps separate from corporate apps. That way, when an employee leaves the company, you can easily remove all the corporate apps without touching any of the personal ones. Best Practice #6: Use TouchDown for Setting up (Android Only) With NitroDesk s TouchDown product, you can encrypt s and attachments, prevent unauthorized backups, prevent copying and pasting contacts or s, and can block attachments from Android devices. It also gives your users a consistent experience, even if they are on different versions of Android. 1. Block native capabilities on the device 2. Block Gmail 3. Require users to have TouchDown 4. Encrypt s 5. Encrypt attachments There s an added bonus, too: it s easier to remove corporate settings when employees leave the company. MaaS360 lets you include TouchDown settings in your policy for Android devices. 11

12 Best Practice #7: Distribute Settings Over the Air (OTA) Your wireless network, VPN and passcode settings will probably be the same for all your users. Configuring them all individually would be a lot of extra time and trouble for your IT department. Some MDM solutions will let you create settings once and then push them to your users. Use a policy to push your wireless network, VPN and passcode settings to your users. If you push them OTA, you won t have to touch each device. That can save your IT department a great deal of time and effort. There s an added bonus, too: you don t have to track down all your users and get their devices. When someone leaves the company, you can remove their access and data the same way. You don t need to try to track down someone s personal device as they re leaving just remove the settings and information remotely. MaaS360 allows you to set up these profiles for your users in minutes. Then you can push them to your users OTA. When someone leaves the company, you can remove the profiles remotely, using the Remote Control action. 12

13 Best Practice #8: Warn First, Then Remediate Policy Violations When your users do something that puts them out of compliance, it s a good idea to give them some kind of notice. Although you probably have the ability to take action right away, a better approach is to send them a message and let them remediate the noncompliance on their own. Set up device management options to automatically handle out of compliance situations. Send users a message explaining the company s policy and why they are out of compliance with it. In most cases, you can give them some time to fix the problem before taking action (although there are exceptions). Your MDM solution should be able to do all this automatically, without your IT department having to learn of the problem and then take action. With MaaS360 s Compliance Engine you can set up automatic enforcement actions. You can set up enforcement actions for a number of scenarios. Each one can be handled differently everything from a sending a simple to the Administrator to remotely performing a selective wipe. Best of all, this can be done without your IT department s involvement. 13

14 Best Practice #9: Test Your Policies Before you deploy a policy to any of your users, you should first deploy it to test users. This is especially important if you have a lot of users. MaaS360 allows you designate a group of users as test users. With a few clicks you can deploy a new policy to those devices so the users can experiment with it. If there s a problem, you can roll back the policy and edit it. If not, you can publish the policy to the actual users. 14

15 Best Practice #10: Monitor Your Devices After your policies are in place, you ll want to make sure your users are following them. Your MDM solution should provide you with statistics on how compliant your devices are. You should be able to see how many devices are out of compliance, and which devices they are. The Home page displays My Alert Center, a dashboard of important information that you can customize to meet the needs of your organization. The alerts are red, green or blue. Security alerts can be red or green, depending on if the situation needs attention. Information alerts are blue. When you know which devices are out of compliance, you can take the appropriate action, based on your industry s rules and regulations. All brands and their products, featured or referred to within this document, are trademarks or registered trademarks of their respective holders and should be noted as such. For More Information To learn more about our technology and services visit Sentry Parkway West, Building 18, Suite 200 Blue Bell, PA Phone Fax WP_201402_

Managing Mobility 10 top tips for Enterprise Mobility Management About Trinsic Trinsic is a new kind of business communications specialist, built from the ground up to help your organisation leave behind

MaaS360 FAQs This guide is meant to help answer some of the initial frequently asked questions businesses ask as they try to figure out the who, what, when, why and how of managing their smartphone devices,

Using the Apple Configurator and MaaS3360 Overview Apple Configurator Utility (ACU) is a free Apple tool that enables a Mac to configure up to 30 ios devices simultaneously via a USB. There are two modes

Advanced Configuration Steps After you have downloaded a trial, you can perform the following from the Setup menu in the MaaS360 portal: Configure additional services Configure device enrollment settings

SYNCSHIELD FEATURES This document describes the diversity of SyncShield features. Please note that many of the features require a certain platform version, often earlier software versions do not support

Financial Mobility Balancing Security and Success Fiberlink, MaaS360, associated logos, and the names of the products and services of Fiberlink are marks, brands, logos, and symbols may be trademarks or

Apple Push Notification Service (APNS) TERMS AppleID The account used to log in to Apple Certificates Portal, purchase VPP codes, etc. Fiberlink recommends using an AppleID associated with a publically-facing

MaaS360 Mobile Enterprise Gateway Administrator Guide Copyright 2014 Fiberlink, an IBM Company. All rights reserved. Information in this document is subject to change without notice. The software described

Android support for Microsoft Exchange in pure Google devices Note: The information presented here is intended for Microsoft Exchange administrators who are planning and implementing support for any of

Mobile Device Management for the Agile Enterprise December 2012 Copyright 2012 ICS Nett, Inc. All rights reserved. This document contains proprietary and confidential information of ICS Nett. No part of

EXECUTIVE SUMMARY Cloud Backup for Endpoint Devices According to Gartner, by 2015 more than 60% of enterprises will have suffered material loss of sensitive corporate data via mobile devices. Armed with

Oracle Mobile Security What s New in OMSS 11gR2 Patch Set 3 ORACLE WHITE PAPER MAY 2015 Disclaimer The following is intended to outline our general product direction. It is intended for information purposes

Learn More MaaS360 Cloud Extender Checklist (MDM for Blackberry) June 2011 Copyright 2011 Fiberlink Communications Corporation. All rights reserved. Information in this document is subject to change without

award winning devices and solutions for business welcome to HTCpro HTCpro is an established programme designed for business that delivers a comprehensive suite of enterprise-grade mobile solutions. These

June 2012 Sy mantec Corporation, 2012 Page 1 Purpose of Document This document provides a guide for users of App Center to set up and use Mobile Device Management (MDM) capabilities. MDM allows the App

Cloud Backup and Recovery for Endpoint Devices Executive Summary Armed with their own devices and faster wireless speeds, your employees are looking to access corporate data on the move. They are creating,

Cisco Mobile Collaboration Management Service Cisco Collaboration Services Business is increasingly taking place on both personal and company-provided smartphones and tablets. As a result, IT leaders are

Deploying iphone and ipad Security Overview ios, the operating system at the core of iphone and ipad, is built upon layers of security. This enables iphone and ipad to securely access corporate services

USER GUIDE: MaaS360 Services 05.2010 Copyright 2010 Fiberlink Corporation. All rights reserved. Information in this document is subject to change without notice. The software described in this document

Mobile Device Management Buyers Guide IT departments should be perceived as the lubricant in the machine that powers an organization. BYOD is a great opportunity to make life easier for your users. But

Security Guide BlackBerry Enterprise Service 12 for ios, Android, and Windows Phone Version 12.0 Published: 2015-02-06 SWD-20150206130210406 Contents About this guide... 6 What is BES12?... 7 Key features

Sophos Mobile Control User guide for Android Product version: 4 Document date: May 2014 Contents 1 About Sophos Mobile Control...3 2 About this guide...4 3 Login to the Self Service Portal...5 4 Set up

Deploying iphone and ipad Apple Configurator ios devices can be configured for enterprise deployment using a wide variety of tools and methods. End users can set up devices manually with a few simple instructions

Android EMM Enrollment Before starting the device enrollment procedure, make sure your device is disconnected from the WUSM-Secure wireless network. Use either the Guest wireless network, or your mobile

Mobile Security: Controlling Growing Threats with Mobile Device Management As the use of mobile devices continues to grow, so do mobile security threats. Most people use their mobile devices for both work

Management Options ios New Market ipads - January 2010 Several changes in a short period of time. Apple Lion Server came out June 2011. Apple Configurator came out in June 2012. Why Absolute or Alteris?

Creating a Google Play Account Updated March, 2014 One of the most effective ways to get your application into users hands is to publish it on an application marketplace like Google Play. This document

Acronis 2002-2014 Introduction When enterprise mobility strategies are discussed, security is usually one of the first topics on the table. So it should come as no surprise that Acronis Access Advanced

Rutgers Biomedical and Health Sciences (RBHS) has implemented security controls to be applied to all mobile devices (Smart Phones and tablets) that contain RBHS (NJMS) email. These controls have been established

Whitepaper Choosing an MDM Platform Where to Start the Conversation 2 Choosing an MDM Platform: Where to Start the Conversation There are dozens of MDM options on the market, each claiming to do more than

We secure your information world www. Mobile Security Features What are the new security features in Android KitKat 4.4 and IOS 7?. IOS Feature 1 Single Sign-on Previously available for multiple apps developed

Building a BYOD Program Using the Casper Suite Technical Paper Casper Suite v9.4 or Later 17 September 2014 JAMF Software, LLC 2014 JAMF Software, LLC. All rights reserved. JAMF Software has made all efforts